课题基金 / 基金详情

Improving security and usability of user authentication on the Internet with adversarial machine learning

Improving security and usability of user authentication on the Internet with adversarial machine learning
通过对抗性机器学习提高互联网上用户身份验证的安全性和可用性
批准号:
429816072
负责人:
Professor Dr. Markus Dürmuth
金额:
$0.0万
依托单位:
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
--
资助国家:
德国
项目状态:
未结题
起止时间:

项目摘要

项目成果

Professor Dr. Markus Dürmuth的其他基金

相似基金

相关文献

中文摘要
翻译
基于密码的身份验证在互联网上得到了广泛的应用。然而,当登录到一个帐户,通常有更多的数据比只是密码,如一天中的时间,源IP和地理位置,软件设置,仅举几例。在这个项目中,我们研究如何使用这些“行为”信息可以改善用户体验的登录过程,并提高安全性和可用性。 这种方法的一个核心优势是它相对容易大规模部署,因为它不需要改变用户界面,也不需要改变客户端软件和硬件。其基本思想是使用机器学习技术将行为数据分类为“合法”或“非法”。 这就引出了几个有趣的问题:哪些特征是可用的,这些特征的可靠性如何,以及哪些分类器对这个应用程序有最好的区分能力。 虽然我们知道一些网站使用的行为特征集有限,但它们的细节被认为是公司机密,其有效性几乎没有得到科学的研究。使用分类器来辅助认证决策会产生一种针对分类器本身的新型攻击,试图绕过或影响分类器。 这被称为对抗性机器学习,通常在垃圾邮件预防的背景下进行研究;它从未在用户身份验证的背景下被考虑过。 我们将考虑针对不同分类器的对抗性攻击,构建预防措施,并旨在将对抗性机器学习的先前工作扩展到用户身份验证的背景下。 我们相信,新的背景下所需的新模型和需求将显示出超出这个特定项目的新的研究方向。
英文摘要
Password-based authentication is widely used on the Internet. However, when login into an account there is usually much more data available than just the password, such time of day, origin IP and geo-location, software setup, just to name a few.In this project, we study how this "behavioral" information can be used to improve the user experience of the login procedure andincrease both security and usability. One central advantage of this approach is that it is relatively easy to deploy on a large scale, asit does not change the user interface and does not require changes to the client-side software and hardware.The basic idea is to use machine learning techniques to classify behavioral data as "legitimate" or "illegitimate". This leads toseveral interesting questions: which features are available, how reliable are these features, and which classifiers have the bestdiscriminatory power for this application. While it is known that some websites use a limited set of behavioral features, their detailsare considered corporate secrets and their effectiveness has hardly been scientifically studied.Using classifiers to aid the authentication decision gives rise to a new type of attacks which target the classifier itself, trying tocircumvent or influence the classifier. This is known as adversarial machine learning and is usually studied in the context of spamprevention; it has never been considered in the context of user authentication. We will consider adversarial attacks againstdifferent classifiers, construct preventative measures, and aim to extend the previous work on adversarial machine learning to thecontext of user authentication. We believe that the new models and requirements required for the new context will show new researchdirections beyond this specific project.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
ImPAKT: Real-World Implementation and Human-Centered Design of PAKE Technologies
  • 批准号:
    490855785
  • 项目类别:
    Research Grants
  • 资助金额:
    $0.0万
  • 财政年份:
    --
  • 负责人:
    Professor Dr. Markus Dürmuth
  • 依托单位:
国内基金
海外基金
黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
存储安全中介系统理论、仿真和实现技术研究
  • 批准号:
    61070154
  • 项目类别:
    面上项目
  • 资助金额:
    30.0万元
  • 批准年份:
    2010
  • 负责人:
    韩德志
  • 依托单位:
最优证券设计及完善中国资本市场的路径选择
  • 批准号:
    70873012
  • 项目类别:
    面上项目
  • 资助金额:
    27.0万元
  • 批准年份:
    2008
  • 负责人:
    彭龙
  • 依托单位: